A AegiFlow
LOWCVSS 2.3EPSS 0.4%

CVE-2026-61712

CVE-2026-61712 updated by NVD

Published
2026-08-19
Modified
2026-09-11
EPSS percentile
34%
Sources
github-advisory, nvd

Summary

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolving a username to a user identifier or group identifier in executor/oci/user.go and solver/llbsolver/ops/user_linux.go. A malicious base image or build could provide oversized files that exhausted memory during user resolution and caused out-of-memory termination of the buildkitd process. This issue is fixed in version 0.31.1.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/moby/buildkit0.31.1

Remediation: Upgrade to 0.31.1 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.